Session

Falco + eBPF: The Missing Layer in AWS Security

Cloud security doesn’t end at IAM policies or API activity logs. Modern attackers exploit the runtime layer, executing commands inside containers, launching privilege escalation attempts or opening unauthorized network connections, all of which are well below the visibility of traditional tools.

In this talk we will explore how Falco, together with eBPF, brings real time, kernel-level threat detection to your AWS workloads. You’ll learn how to uncover hidden behaviors like container escapes, unexpected syscalls, and malicious process executions using customizable detection rules.

We will dive into the internals of Falco, break down how eBPF captures system activity, and show you how to build and tune rules that matter to your environment.
At the end of the talk, we will simulate a real attack and walk through how Falco can catch it instantly, before any damage is done.

Irine Kokilashvili

GPU sharing + Cloud + Rust

Tbilisi, Georgia

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top